Lawmakers in the United States (US) and the European Union (EU) have called for probes into how Facebook allowed Cambridge Analytica to access data on 50 million users and use it to help the election campaign of President Donald Trump.

Facebook shares have fallen 8.5 per cent this week as investors fear the incident will lead to new regulation.

The scrutiny and the risk of regulatory action could affect Alphabet’s Google, Twitter, Uber Technologies, Microsoft’s LinkedIn platform and the many others that make their user data available to outside developers.

The interconnections between platforms such as Facebook and Google and third-party services sit at the core of the contemporary internet, enabling people to quickly share articles to Facebook from news websites and log into shopping apps using their Google account.

But the Facebook case has turned the application programming interfaces, or APIs, that enable such data sharing, into a new front in the escalating battle between lawmakers and tech companies over the monitoring and securing of their vast platforms. Threat of sanctions has already prodded companies into better policing of inappropriate commentary on their services.

"All companies are going to need to do a lot more than just laissez faire policy to manage third-party data access moving forward," said Jason Costa, who helped run APIs at Pinterest, Twitter and Google and now works at GGV Capital.

"The days of (the) 'we're just a platform and can't be held responsible for how users use it' line that many companies use, is no longer going to be tenable."

APIs have raised privacy concerns since they emerged around 2005, but their adoption and impact has grown rapidly as companies move data online and look for ways to make it more useful.

Uber, for example, in 2016 enabled apps that provided tax and lending services to import driver paystubs. The company did not respond to a request for comment on its monitoring and auditing practices.

The economic dynamic behind APIs is simple: software developers create new tools that benefit big tech companies' users, and in return they gain instant access to a large number of consumers.

The big platforms say they have built in protection, such as human reviews and automated scanning tools to detect abuse by partners.

But software experts say policies are toothless because auditing is lax; Facebook CEO Mark Zuckerberg, under intense public pressure, said Wednesday the company would now perform audits of the information it shared with partners before it tightened rules in 2014.

Dartmouth University engineering professor Geoffrey Parker, who has assigned students to develop apps based on APIs, said automated policing methods will detect spam-like apps and brazen efforts to steal data. It is much more difficult to enforce bans on storing or mashing together information, or acting against users' interest, he said.

Some companies added safeguards in the last several years. Facebook stopped allowing developers access to information on its users' friends. But compliance audits were minimal, a former employee said on the condition of anonymity.

Twitter and LinkedIn limited free public access.

For paid deals, LinkedIn said "partners are rigorously vetted and regularly declined." The company added that it regularly monitors API usage and takes "swift action when we see or hear of any abuse of our terms."

Software developers acknowledged they often do not even read the terms of use for APIs. Rule-breakers can fly under the radar and amass significant information, said Andres Blank, chief executive of recruiting software maker Scout.

"It's hard to police if the alarms aren't being sounded," said Blank, who has worked with APIs from LinkedIn and Google.

Alex Moore, chief executive of Baydin, which develops Boomerang, an app that can send emails on time-delay, said Microsoft scrutinized his services when the companies partnered on a new feature. But he was not aware of any auditing after it launched.

Google recently asked whether Boomerang could access less information, but that was a rare "poke," Moore said.

"There's going to be things people took for granted about data sharing that come to light," he said.

Google declined to comment. Microsoft did not respond to a request to comment.

Clamping down could limit the supply of innovative tools built on data sharing. But some providers, including Royal Bank of Canada, which announced an API this week, have gone a step further to only allow access to vetted partners.

Paul Nerger, senior vice president at Developerprogram.com, which helps companies such as Cisco Systems manage APIs, said clients have limited the number of partners so that software can be tested "to make sure they are not illegally harvesting" data.

Startups are taking heed too. Affectiva, which last year released an API for identifying consumers' emotional states from speech samples, said that it would audit partners as its program grows.

Gabi Zijderveld, the company's chief marketing officer and head of product strategy, said, though, "we inevitably need regulation and legislation on ethical and transparent use of data."

(Reporting by Paresh Dave; Additional reporting by David Ingram; Editing by Jonathan Weber and Neil Fullick)

The making of an MSSP: a blueprint for growth in NZ

Partners are actively building out security practices and services to match, yet remain challenged by a lack of guidance in the market. This exclusive Reseller News Roundtable - in association with Sophos - assessed the making of an MSSP, outlining the blueprint for growth and how partners can differentiate in New Zealand.

Reseller News Platinum Club celebrates leading partners in 2018

The leading players of the New Zealand channel came together to celebrate a year of achievement at the inaugural Reseller News Platinum Club lunch in Auckland. Following the Reseller News Innovation Awards, Platinum Club provides a platform to showcase the top performing partners and start-ups of the past 12 months, with more than ​​50 organisations in the spotlight.​​​

Copyright 2019 IDG Communications. ABN 14 001 592 650. All rights reserved. Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.